¡¾Îó²îͨ¸æ¡¿VMware Aria Operations for LogsÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2023-34051£©
Ðû²¼Ê±¼ä 2023-10-25Ò»¡¢Îó²î¸ÅÊö
CVE ID | CVE-2023-34051 | ·¢Ã÷ʱ¼ä | 2023-10-23 |
Àà ÐÍ | Éí·ÝÑéÖ¤ÈÆ¹ý | µÈ ¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
¹¥»÷ÖØÆ¯ºó | ¸ß | Óû§½»»¥ | ÎÞ |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ֪ |
VMware Aria Operations for Logs£¨ÒÔǰ³ÆÎª vRealize Log Insight£©ÊÇÒ»¿îÈÕÖ¾ÆÊÎö¹¤¾ß£¬£¬£¬£¬£¬£¬£¬¿ÉÌṩ¸ß¶È¿ÉÀ©Õ¹µÄÒì¹¹ÈÕÖ¾ÖÎÀí¹¦Ð§£¬£¬£¬£¬£¬£¬£¬¾ß±¸Ö±¹ÛÇҿɲÙ×÷µÄÒDZí°å¡¢Ï¸ÄåµÄÆÊÎö¹¦Ð§ºÍÆÕ±éµÄµÚÈý·½À©Õ¹¹¦Ð§¡£¡£¡£
10ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬£¬ÍòÀû¹ú¼Ê¹ÙÍøVSRC¼à²âµ½VMwareÐÞ¸´ÁËVMware Aria Operations for Logs ÖеÄÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2023-34051£©£¬£¬£¬£¬£¬£¬£¬CVSSv3ÆÀ·ÖΪ8.1£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚ¸ÃÎó²îµÄϸ½ÚÒÑÔÚ»¥ÁªÍøÉϹûÕæ¡£¡£¡£
¸ÃÎó²îÔ´ÓÚVMware vRealize Log InsightÖжÔÏÈǰÐû²¼µÄVMSA-2023-0001ÖеĶà¸öÎó²îÐÞ¸´È±·¦£¨½ö×èֹͨ¹ýIP»á¼ûThrift ЧÀÍ£©£¬£¬£¬£¬£¬£¬£¬µ¼Ö±£´æÈƹýVMSA-2023-0001²¹¶¡µÄÉí·ÝÑéÖ¤ÈÆ¹ýÒªÁì¡£¡£¡£ÏÖÔÚ¸ÃÎó²îµÄPoCÒѹûÕæ£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÀÄÓÃIPµØµãÓÕÆºÍÖÖÖÖThrift RPC¶ËµãÀ´ÊµÏÖí§ÒâÎļþдÈ룬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓÿÉʹÓÃroot ȨÏÞÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬£¬£¬VMware Aria Operations for LogsÖл¹ÐÞ¸´ÁËÁíÒ»¸ö·´ÐòÁл¯Îó²î£¨CVE-2023-34052£¬£¬£¬£¬£¬£¬£¬CVSSv3ÆÀ·ÖΪ8.1£©£¬£¬£¬£¬£¬£¬£¬¶ÔÍâµØÏµÍ³¾ßÓзÇÖÎÆÊÎö¼ûȨÏ޵ĶñÒâÐÐΪÕß¿ÉÒÔ´¥·¢Êý¾Ý·´ÐòÁл¯£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÉí·ÝÑéÖ¤ÈÆ¹ý¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
VMware Aria Operations for Logs 8.x < 8.14
VMware Cloud Foundation (VMware Aria Operations for Logs) 5.x¡¢4.x
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÖÔÚÕâЩÎó²îÒѾÐÞ¸´£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½ÒÔϰ汾£º
VMware Aria Operations for Logs 8.x£ºÉý¼¶µ½8.14
VMware Cloud Foundation (VMware Aria Operations for Logs) 5.x¡¢4.x£º²Î¿¼KB95212
ÏÂÔØÁ´½Ó£º
https://customerconnect.vmware.com/en/downloads/info/slug/infrastructure_operations_management/vmware_aria_operations_for_logs/8_14
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£
3.3 ͨÓý¨Òé
l °´ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¡£¬£¬£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£
l ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£
l ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£
l ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£
l ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://www.vmware.com/security/advisories/VMSA-2023-0021.html
https://www.horizon3.ai/vmware-aria-operations-for-logs-cve-2023-34051-technical-deep-dive-and-iocs/
https://www.vmware.com/security/advisories/VMSA-2023-0001.html
ËÄ¡¢°æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ±¸×¢ |
V1.0 | 2023-10-25 | Ê×´ÎÐû²¼ |
Îå¡¢¸½Â¼
5.1 ÍòÀû¹ú¼Ê¹ÙÍø¼ò½é
ÍòÀû¹ú¼Ê¹ÙÍø½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°ÍòÀû¹ú¼Ê¹ÙÍø´óÏ㬣¬£¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬£¬£¬£¬£¬£¬£¬ÍòÀû¹ú¼Ê¹ÙÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£
5.2 ¹ØÓÚÍòÀû¹ú¼Ê¹ÙÍø
ÍòÀû¹ú¼Ê¹ÙÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬£¬£¬£¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬£¬£¬£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£
¹Ø×¢ÎÒÃÇ£º



¾©¹«Íø°²±¸11010802024551ºÅ